I followed the linked howto sans the ipv6 pieces as I had no ipv6 target range anywhere to be used. I can connect just fine with that. Before I do that it would be easier for you to check if dropping the ipv6 lines from the server conf make it work. If it does - then we know it only affects the ipv6 handling that you have set up. If it does not work we can kill all thoughts on ipv6 while searching for the root cause. I'm still wondering why the version from upstream should work, at least that is a lead we can continue to try to sort out. The systemd file of Debian/Ubunut seems a bit more evolved to me, but maybe one of these configs is the reasons that your specific case fails. I compared the services: --- upstream.service 2018-08-24 07:40:11.302369502 +0000 +++ ubuntu.service 2018-08-24 07:37:09.014566529 +0000 @@ -3,25 +3,28 @@ PartOf=openvpn.service ReloadPropagatedFrom=openvpn.service Before=systemd-user-sessions.service +After=network-online.target +Wants=network-online.target Documentation=man:openvpn(8) -Documentation=https://community.openvpn.net/openvpn/wiki/Openvpn23ManPage +Documentation=https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage Documentation=https://community.openvpn.net/openvpn/wiki/HOWTO [Service] +Type=notify PrivateTmp=true -KillMode=mixed -Type=forking +WorkingDirectory=/etc/openvpn ExecStart=/usr/sbin/openvpn --daemon ovpn-%i --status /run/openvpn/%i.status 10 --cd /etc/openvpn --script-security 2 --config /etc/openvpn/%i.conf --writepid /run/openvpn/%i.pid PIDFile=/run/openvpn/%i.pid +KillMode=process ExecReload=/bin/kill -HUP $MAINPID -WorkingDirectory=/etc/openvpn -ProtectSystem=yes -CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_READ_SEARCH CAP_AUDIT_WRITE +CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE LimitNPROC=10 DeviceAllow=/dev/null rw DeviceAllow=/dev/net/tun rw +ProtectSystem=true +ProtectHome=true +RestartSec=5s +Restart=on-failure [Install] WantedBy=multi-user.target In many cases I think the changes are fine for sure, but a few would be candidates for you to try. IMHO Those worth to try are: #1 -CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_READ_SEARCH CAP_AUDIT_WRITE +CapabilityBoundingSet=CAP_IPC_LOCK CAP_NET_ADMIN CAP_NET_BIND_SERVICE CAP_NET_RAW CAP_SETGID CAP_SETUID CAP_SYS_CHROOT CAP_DAC_OVERRIDE #2 +ProtectSystem=true #3 +ProtectHome=true I'd ask you to check the following: 1. please verify without ipv6 settings (you see in my configs below which ones I removed) if the issue persists 2. Try the three changes - best would be to set up the upstream version that works and then add the changes #1/#2/#3 one by one restarting and retrying. Maybe one of those blocks something that is needed in your case? Looking forward to hear from you ... My test setup: client.conf client dev tun proto udp remote 192.168.122.29 1194 resolv-retry infinite nobind persist-key persist-tun ca /etc/openvpn/easy-rsa/pki/ca.crt cert /etc/openvpn/easy-rsa/pki/issued/guest1.crt key /etc/openvpn/easy-rsa/pki/private/guest1.key remote-cert-tls server cipher AES-256-CBC tls-version-min 1.2 tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 auth SHA512 comp-lzo verb 6 explicit-exit-notify server.conf port 1194 proto udp dev tun ca /etc/openvpn/easy-rsa/pki/ca.crt cert /etc/openvpn/easy-rsa/pki/issued/server.crt key /etc/openvpn/easy-rsa/pki/private/server.key dh /etc/openvpn/easy-rsa/pki/dh.pem topology subnet server 10.8.0.0 255.255.255.0 ifconfig-pool-persist ipp.txt script-security 2 push "redirect-gateway def1" push "dhcp-option DNS 8.8.8.8" keepalive 10 120 tls-version-min 1.2 tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 auth SHA512 cipher AES-256-CBC comp-lzo persist-key persist-tun status openvpn-status.log verb 6 user openvpn group openvpn Full client output until completing initialization: $ openvpn /etc/openvpn/client.conf Fri Aug 24 07:27:25 2018 us=469591 Current Parameter Settings: Fri Aug 24 07:27:25 2018 us=469791 config = '/etc/openvpn/client.conf' Fri Aug 24 07:27:25 2018 us=469987 mode = 0 Fri Aug 24 07:27:25 2018 us=470179 persist_config = DISABLED Fri Aug 24 07:27:25 2018 us=470368 persist_mode = 1 Fri Aug 24 07:27:25 2018 us=470558 show_ciphers = DISABLED Fri Aug 24 07:27:25 2018 us=470745 show_digests = DISABLED Fri Aug 24 07:27:25 2018 us=470933 show_engines = DISABLED Fri Aug 24 07:27:25 2018 us=471121 genkey = DISABLED Fri Aug 24 07:27:25 2018 us=471563 key_pass_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=471757 show_tls_ciphers = DISABLED Fri Aug 24 07:27:25 2018 us=471947 connect_retry_max = 0 Fri Aug 24 07:27:25 2018 us=472357 Connection profiles [0]: Fri Aug 24 07:27:25 2018 us=472490 proto = udp Fri Aug 24 07:27:25 2018 us=472620 local = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=472750 local_port = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=472867 remote = '192.168.122.29' Fri Aug 24 07:27:25 2018 us=472995 remote_port = '1194' Fri Aug 24 07:27:25 2018 us=473148 remote_float = DISABLED Fri Aug 24 07:27:25 2018 us=473270 bind_defined = DISABLED Fri Aug 24 07:27:25 2018 us=473400 bind_local = DISABLED Fri Aug 24 07:27:25 2018 us=473530 bind_ipv6_only = DISABLED Fri Aug 24 07:27:25 2018 us=473654 connect_retry_seconds = 5 Fri Aug 24 07:27:25 2018 us=473782 connect_timeout = 120 Fri Aug 24 07:27:25 2018 us=473911 socks_proxy_server = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=474043 socks_proxy_port = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=474155 tun_mtu = 1500 Fri Aug 24 07:27:25 2018 us=474270 tun_mtu_defined = ENABLED Fri Aug 24 07:27:25 2018 us=474825 link_mtu = 1500 Fri Aug 24 07:27:25 2018 us=474956 link_mtu_defined = DISABLED Fri Aug 24 07:27:25 2018 us=475073 tun_mtu_extra = 0 Fri Aug 24 07:27:25 2018 us=475149 tun_mtu_extra_defined = DISABLED Fri Aug 24 07:27:25 2018 us=475225 mtu_discover_type = -1 Fri Aug 24 07:27:25 2018 us=475255 fragment = 0 Fri Aug 24 07:27:25 2018 us=475271 mssfix = 1450 Fri Aug 24 07:27:25 2018 us=475331 explicit_exit_notification = 1 Fri Aug 24 07:27:25 2018 us=475348 Connection profiles END Fri Aug 24 07:27:25 2018 us=475361 remote_random = DISABLED Fri Aug 24 07:27:25 2018 us=475435 ipchange = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475453 dev = 'tun' Fri Aug 24 07:27:25 2018 us=475526 dev_type = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475554 dev_node = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475617 lladdr = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475645 topology = 1 Fri Aug 24 07:27:25 2018 us=475708 ifconfig_local = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475736 ifconfig_remote_netmask = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475800 ifconfig_noexec = DISABLED Fri Aug 24 07:27:25 2018 us=475817 ifconfig_nowarn = DISABLED Fri Aug 24 07:27:25 2018 us=475889 ifconfig_ipv6_local = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=475917 ifconfig_ipv6_netbits = 0 Fri Aug 24 07:27:25 2018 us=475981 ifconfig_ipv6_remote = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=476031 shaper = 0 Fri Aug 24 07:27:25 2018 us=476102 mtu_test = 0 Fri Aug 24 07:27:25 2018 us=476120 mlock = DISABLED Fri Aug 24 07:27:25 2018 us=476191 keepalive_ping = 0 Fri Aug 24 07:27:25 2018 us=476219 keepalive_timeout = 0 Fri Aug 24 07:27:25 2018 us=476282 inactivity_timeout = 0 Fri Aug 24 07:27:25 2018 us=476310 ping_send_timeout = 0 Fri Aug 24 07:27:25 2018 us=476372 ping_rec_timeout = 0 Fri Aug 24 07:27:25 2018 us=476400 ping_rec_timeout_action = 0 Fri Aug 24 07:27:25 2018 us=476462 ping_timer_remote = DISABLED Fri Aug 24 07:27:25 2018 us=476534 remap_sigusr1 = 0 Fri Aug 24 07:27:25 2018 us=476565 persist_tun = ENABLED Fri Aug 24 07:27:25 2018 us=476582 persist_local_ip = DISABLED Fri Aug 24 07:27:25 2018 us=476642 persist_remote_ip = DISABLED Fri Aug 24 07:27:25 2018 us=476669 persist_key = ENABLED Fri Aug 24 07:27:25 2018 us=476733 passtos = DISABLED Fri Aug 24 07:27:25 2018 us=476761 resolve_retry_seconds = 1000000000 Fri Aug 24 07:27:25 2018 us=476824 resolve_in_advance = DISABLED Fri Aug 24 07:27:25 2018 us=476852 username = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=476914 groupname = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=476942 chroot_dir = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477004 cd_dir = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477031 writepid = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477094 up_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477202 down_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477227 down_pre = DISABLED Fri Aug 24 07:27:25 2018 us=477293 up_restart = DISABLED Fri Aug 24 07:27:25 2018 us=477313 up_delay = DISABLED Fri Aug 24 07:27:25 2018 us=477385 daemon = DISABLED Fri Aug 24 07:27:25 2018 us=477414 inetd = 0 Fri Aug 24 07:27:25 2018 us=477479 log = DISABLED Fri Aug 24 07:27:25 2018 us=477497 suppress_timestamps = DISABLED Fri Aug 24 07:27:25 2018 us=477571 machine_readable_output = DISABLED Fri Aug 24 07:27:25 2018 us=477599 nice = 0 Fri Aug 24 07:27:25 2018 us=477663 verbosity = 6 Fri Aug 24 07:27:25 2018 us=477689 mute = 0 Fri Aug 24 07:27:25 2018 us=477753 gremlin = 0 Fri Aug 24 07:27:25 2018 us=477770 status_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=477844 status_file_version = 1 Fri Aug 24 07:27:25 2018 us=477872 status_file_update_freq = 60 Fri Aug 24 07:27:25 2018 us=477935 occ = ENABLED Fri Aug 24 07:27:25 2018 us=477962 rcvbuf = 0 Fri Aug 24 07:27:25 2018 us=478026 sndbuf = 0 Fri Aug 24 07:27:25 2018 us=478053 mark = 0 Fri Aug 24 07:27:25 2018 us=478116 sockflags = 0 Fri Aug 24 07:27:25 2018 us=478190 fast_io = DISABLED Fri Aug 24 07:27:25 2018 us=478220 comp.alg = 2 Fri Aug 24 07:27:25 2018 us=478236 comp.flags = 1 Fri Aug 24 07:27:25 2018 us=478296 route_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=478313 route_default_gateway = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=478387 route_default_metric = 0 Fri Aug 24 07:27:25 2018 us=478414 route_noexec = DISABLED Fri Aug 24 07:27:25 2018 us=478478 route_delay = 0 Fri Aug 24 07:27:25 2018 us=478506 route_delay_window = 30 Fri Aug 24 07:27:25 2018 us=478569 route_delay_defined = DISABLED Fri Aug 24 07:27:25 2018 us=478586 route_nopull = DISABLED Fri Aug 24 07:27:25 2018 us=478659 route_gateway_via_dhcp = DISABLED Fri Aug 24 07:27:25 2018 us=478677 allow_pull_fqdn = DISABLED Fri Aug 24 07:27:25 2018 us=478750 management_addr = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=478778 management_port = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=478842 management_user_pass = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=478870 management_log_history_cache = 250 Fri Aug 24 07:27:25 2018 us=478934 management_echo_buffer_size = 100 Fri Aug 24 07:27:25 2018 us=479009 management_write_peer_info_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=479039 management_client_user = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=479055 management_client_group = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=479068 management_flags = 0 Fri Aug 24 07:27:25 2018 us=479135 shared_secret_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=479164 key_direction = not set Fri Aug 24 07:27:25 2018 us=479227 ciphername = 'AES-256-CBC' Fri Aug 24 07:27:25 2018 us=479255 ncp_enabled = ENABLED Fri Aug 24 07:27:25 2018 us=479320 ncp_ciphers = 'AES-256-GCM:AES-128-GCM' Fri Aug 24 07:27:25 2018 us=479348 authname = 'SHA512' Fri Aug 24 07:27:25 2018 us=479413 prng_hash = 'SHA1' Fri Aug 24 07:27:25 2018 us=479441 prng_nonce_secret_len = 16 Fri Aug 24 07:27:25 2018 us=479505 keysize = 0 Fri Aug 24 07:27:25 2018 us=479523 engine = DISABLED Fri Aug 24 07:27:25 2018 us=479595 replay = ENABLED Fri Aug 24 07:27:25 2018 us=479613 mute_replay_warnings = DISABLED Fri Aug 24 07:27:25 2018 us=479686 replay_window = 64 Fri Aug 24 07:27:25 2018 us=479715 replay_time = 15 Fri Aug 24 07:27:25 2018 us=479778 packet_id_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=479796 use_iv = ENABLED Fri Aug 24 07:27:25 2018 us=479868 test_crypto = DISABLED Fri Aug 24 07:27:25 2018 us=479942 tls_server = DISABLED Fri Aug 24 07:27:25 2018 us=479973 tls_client = ENABLED Fri Aug 24 07:27:25 2018 us=479990 key_method = 2 Fri Aug 24 07:27:25 2018 us=480306 ca_file = '/etc/openvpn/easy-rsa/pki/ca.crt' Fri Aug 24 07:27:25 2018 us=480326 ca_path = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480398 dh_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480429 cert_file = '/etc/openvpn/easy-rsa/pki/issued/guest1.crt' Fri Aug 24 07:27:25 2018 us=480445 extra_certs_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480507 priv_key_file = '/etc/openvpn/easy-rsa/pki/private/guest1.key' Fri Aug 24 07:27:25 2018 us=480536 pkcs12_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480600 cipher_list = 'TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256' Fri Aug 24 07:27:25 2018 us=480631 tls_cert_profile = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480696 tls_verify = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480726 tls_export_cert = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480743 verify_x509_type = 0 Fri Aug 24 07:27:25 2018 us=480805 verify_x509_name = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480846 crl_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=480911 ns_cert_type = 0 Fri Aug 24 07:27:25 2018 us=480941 remote_cert_ku[i] = 65535 Fri Aug 24 07:27:25 2018 us=480956 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481017 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481034 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481058 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481146 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481169 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481182 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481246 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481275 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481290 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481351 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481380 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481443 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481471 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481486 remote_cert_ku[i] = 0 Fri Aug 24 07:27:25 2018 us=481546 remote_cert_eku = 'TLS Web Server Authentication' Fri Aug 24 07:27:25 2018 us=481575 ssl_flags = 192 Fri Aug 24 07:27:25 2018 us=481638 tls_timeout = 2 Fri Aug 24 07:27:25 2018 us=481667 renegotiate_bytes = -1 Fri Aug 24 07:27:25 2018 us=481732 renegotiate_packets = 0 Fri Aug 24 07:27:25 2018 us=481761 renegotiate_seconds = 3600 Fri Aug 24 07:27:25 2018 us=481841 handshake_window = 60 Fri Aug 24 07:27:25 2018 us=481869 transition_window = 3600 Fri Aug 24 07:27:25 2018 us=481885 single_session = DISABLED Fri Aug 24 07:27:25 2018 us=481944 push_peer_info = DISABLED Fri Aug 24 07:27:25 2018 us=481973 tls_exit = DISABLED Fri Aug 24 07:27:25 2018 us=482035 tls_auth_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=482062 tls_crypt_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=482123 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482152 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482213 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482241 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482303 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482331 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482392 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482419 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482435 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482496 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482524 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482585 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482613 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482628 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482689 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482716 pkcs11_protected_authentication = DISABLED Fri Aug 24 07:27:25 2018 us=482777 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=482807 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=482870 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=482897 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=482958 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=482986 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483001 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483060 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483088 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483149 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483176 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483191 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483251 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483278 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483339 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483366 pkcs11_private_mode = 00000000 Fri Aug 24 07:27:25 2018 us=483427 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483454 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483469 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483529 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483557 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483618 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483646 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483661 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483721 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483749 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483810 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483837 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483852 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483912 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=483939 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=484029 pkcs11_cert_private = DISABLED Fri Aug 24 07:27:25 2018 us=484117 pkcs11_pin_cache_period = -1 Fri Aug 24 07:27:25 2018 us=484191 pkcs11_id = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=484221 pkcs11_id_management = DISABLED Fri Aug 24 07:27:25 2018 us=484281 server_network = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484312 server_netmask = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484335 server_network_ipv6 = :: Fri Aug 24 07:27:25 2018 us=484398 server_netbits_ipv6 = 0 Fri Aug 24 07:27:25 2018 us=484427 server_bridge_ip = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484490 server_bridge_netmask = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484519 server_bridge_pool_start = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484582 server_bridge_pool_end = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484610 ifconfig_pool_defined = DISABLED Fri Aug 24 07:27:25 2018 us=484626 ifconfig_pool_start = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484686 ifconfig_pool_end = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484715 ifconfig_pool_netmask = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=484776 ifconfig_pool_persist_filename = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=484804 ifconfig_pool_persist_refresh_freq = 600 Fri Aug 24 07:27:25 2018 us=484819 ifconfig_ipv6_pool_defined = DISABLED Fri Aug 24 07:27:25 2018 us=484883 ifconfig_ipv6_pool_base = :: Fri Aug 24 07:27:25 2018 us=484911 ifconfig_ipv6_pool_netbits = 0 Fri Aug 24 07:27:25 2018 us=484927 n_bcast_buf = 256 Fri Aug 24 07:27:25 2018 us=484987 tcp_queue_limit = 64 Fri Aug 24 07:27:25 2018 us=485015 real_hash_size = 256 Fri Aug 24 07:27:25 2018 us=485075 virtual_hash_size = 256 Fri Aug 24 07:27:25 2018 us=485103 client_connect_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=485184 learn_address_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=485260 client_disconnect_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=485290 client_config_dir = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=485352 ccd_exclusive = DISABLED Fri Aug 24 07:27:25 2018 us=485380 tmp_dir = '/tmp' Fri Aug 24 07:27:25 2018 us=485441 push_ifconfig_defined = DISABLED Fri Aug 24 07:27:25 2018 us=485469 push_ifconfig_local = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=485532 push_ifconfig_remote_netmask = 0.0.0.0 Fri Aug 24 07:27:25 2018 us=485559 push_ifconfig_ipv6_defined = DISABLED Fri Aug 24 07:27:25 2018 us=485575 push_ifconfig_ipv6_local = ::/0 Fri Aug 24 07:27:25 2018 us=485653 push_ifconfig_ipv6_remote = :: Fri Aug 24 07:27:25 2018 us=485673 enable_c2c = DISABLED Fri Aug 24 07:27:25 2018 us=485685 duplicate_cn = DISABLED Fri Aug 24 07:27:25 2018 us=485698 cf_max = 0 Fri Aug 24 07:27:25 2018 us=485759 cf_per = 0 Fri Aug 24 07:27:25 2018 us=485789 max_clients = 1024 Fri Aug 24 07:27:25 2018 us=485852 max_routes_per_client = 256 Fri Aug 24 07:27:25 2018 us=485869 auth_user_pass_verify_script = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=485881 auth_user_pass_verify_script_via_file = DISABLED Fri Aug 24 07:27:25 2018 us=485939 auth_token_generate = DISABLED Fri Aug 24 07:27:25 2018 us=485967 auth_token_lifetime = 0 Fri Aug 24 07:27:25 2018 us=486030 port_share_host = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=486048 port_share_port = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=486060 client = ENABLED Fri Aug 24 07:27:25 2018 us=486116 pull = ENABLED Fri Aug 24 07:27:25 2018 us=486143 auth_user_pass_file = '[UNDEF]' Fri Aug 24 07:27:25 2018 us=486160 OpenVPN 2.4.6 x86_64-pc-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [PKCS11] [MH/PKTINFO] [AEAD] built on Aug 20 2018 Fri Aug 24 07:27:25 2018 us=486233 library versions: OpenSSL 1.1.0g 2 Nov 2017, LZO 2.10 Enter Private Key Password: ****** Fri Aug 24 07:27:28 2018 us=476703 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this Fri Aug 24 07:27:28 2018 us=482191 LZO compression initializing Fri Aug 24 07:27:28 2018 us=482717 Control Channel MTU parms [ L:1622 D:1212 EF:38 EB:0 ET:0 EL:3 ] Fri Aug 24 07:27:28 2018 us=482940 Data Channel MTU parms [ L:1622 D:1450 EF:122 EB:406 ET:0 EL:3 ] Fri Aug 24 07:27:28 2018 us=483151 Local Options String (VER=V4): 'V4,dev-type tun,link-mtu 1602,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-256-CBC,auth SHA512,keysize 256,key-method 2,tls-client' Fri Aug 24 07:27:28 2018 us=483319 Expected Remote Options String (VER=V4): 'V4,dev-type tun,link-mtu 1602,tun-mtu 1500,proto UDPv4,comp-lzo,cipher AES-256-CBC,auth SHA512,keysize 256,key-method 2,tls-server' Fri Aug 24 07:27:28 2018 us=483497 TCP/UDP: Preserving recently used remote address: [AF_INET]192.168.122.29:1194 Fri Aug 24 07:27:28 2018 us=483699 Socket Buffers: R=[212992->212992] S=[212992->212992] Fri Aug 24 07:27:28 2018 us=483865 UDP link local: (not bound) Fri Aug 24 07:27:28 2018 us=484055 UDP link remote: [AF_INET]192.168.122.29:1194 Fri Aug 24 07:27:28 2018 us=484542 UDP WRITE [14] to [AF_INET]192.168.122.29:1194: P_CONTROL_HARD_RESET_CLIENT_V2 kid=0 [ ] pid=0 DATA len=0 Fri Aug 24 07:27:28 2018 us=487396 UDP READ [26] from [AF_INET]192.168.122.29:1194: P_CONTROL_HARD_RESET_SERVER_V2 kid=0 [ 0 ] pid=0 DATA len=0 Fri Aug 24 07:27:28 2018 us=487619 TLS: Initial packet from [AF_INET]192.168.122.29:1194, sid=46bb6ea3 62c19636 Fri Aug 24 07:27:28 2018 us=487845 UDP WRITE [22] to [AF_INET]192.168.122.29:1194: P_ACK_V1 kid=0 [ 0 ] Fri Aug 24 07:27:28 2018 us=488630 UDP WRITE [140] to [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ ] pid=1 DATA len=126 Fri Aug 24 07:27:28 2018 us=493367 UDP READ [1200] from [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ 1 ] pid=1 DATA len=1174 Fri Aug 24 07:27:28 2018 us=493840 UDP WRITE [22] to [AF_INET]192.168.122.29:1194: P_ACK_V1 kid=0 [ 1 ] Fri Aug 24 07:27:28 2018 us=494049 UDP READ [1000] from [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ ] pid=2 DATA len=986 Fri Aug 24 07:27:28 2018 us=494429 VERIFY OK: depth=1, CN=Easy-RSA CA Fri Aug 24 07:27:28 2018 us=494754 VERIFY KU OK Fri Aug 24 07:27:28 2018 us=494914 Validating certificate extended key usage Fri Aug 24 07:27:28 2018 us=495040 ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication Fri Aug 24 07:27:28 2018 us=495178 VERIFY EKU OK Fri Aug 24 07:27:28 2018 us=495309 VERIFY OK: depth=0, CN=server Fri Aug 24 07:27:28 2018 us=499042 UDP WRITE [1200] to [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ 2 ] pid=2 DATA len=1174 Fri Aug 24 07:27:28 2018 us=499250 UDP WRITE [890] to [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ ] pid=3 DATA len=876 Fri Aug 24 07:27:28 2018 us=500268 UDP READ [22] from [AF_INET]192.168.122.29:1194: P_ACK_V1 kid=0 [ 2 ] Fri Aug 24 07:27:28 2018 us=502016 UDP READ [77] from [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ 3 ] pid=3 DATA len=51 Fri Aug 24 07:27:28 2018 us=502392 UDP WRITE [431] to [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ 3 ] pid=4 DATA len=405 Fri Aug 24 07:27:28 2018 us=505577 UDP READ [263] from [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ 4 ] pid=4 DATA len=237 Fri Aug 24 07:27:28 2018 us=505783 UDP WRITE [22] to [AF_INET]192.168.122.29:1194: P_ACK_V1 kid=0 [ 4 ] Fri Aug 24 07:27:28 2018 us=505966 Control Channel: TLSv1.2, cipher TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256, 2048 bit RSA Fri Aug 24 07:27:28 2018 us=506116 [server] Peer Connection Initiated with [AF_INET]192.168.122.29:1194 Fri Aug 24 07:27:29 2018 us=550459 SENT CONTROL [server]: 'PUSH_REQUEST' (status=1) Fri Aug 24 07:27:29 2018 us=550753 UDP WRITE [56] to [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=42 Fri Aug 24 07:27:29 2018 us=552636 UDP READ [22] from [AF_INET]192.168.122.29:1194: P_ACK_V1 kid=0 [ 5 ] Fri Aug 24 07:27:29 2018 us=553233 UDP READ [225] from [AF_INET]192.168.122.29:1194: P_CONTROL_V1 kid=0 [ ] pid=5 DATA len=211 Fri Aug 24 07:27:29 2018 us=553485 PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 8.8.8.8,route-gateway 10.8.0.1,topology subnet,ping 10,ping-restart 120,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-256-GCM' Fri Aug 24 07:27:29 2018 us=553808 OPTIONS IMPORT: timers and/or timeouts modified Fri Aug 24 07:27:29 2018 us=554005 OPTIONS IMPORT: --ifconfig/up options modified Fri Aug 24 07:27:29 2018 us=554196 OPTIONS IMPORT: route options modified Fri Aug 24 07:27:29 2018 us=554381 OPTIONS IMPORT: route-related options modified Fri Aug 24 07:27:29 2018 us=554575 OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified Fri Aug 24 07:27:29 2018 us=554764 OPTIONS IMPORT: peer-id set Fri Aug 24 07:27:29 2018 us=554949 OPTIONS IMPORT: adjusting link_mtu to 1625 Fri Aug 24 07:27:29 2018 us=555133 OPTIONS IMPORT: data channel crypto options modified Fri Aug 24 07:27:29 2018 us=555320 Data Channel: using negotiated cipher 'AES-256-GCM' Fri Aug 24 07:27:29 2018 us=555522 Data Channel MTU parms [ L:1553 D:1450 EF:53 EB:406 ET:0 EL:3 ] Fri Aug 24 07:27:29 2018 us=555845 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key Fri Aug 24 07:27:29 2018 us=556092 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key Fri Aug 24 07:27:29 2018 us=556465 ROUTE_GATEWAY 192.168.122.1/255.255.255.0 IFACE=ens3 HWADDR=52:54:00:84:73:30 Fri Aug 24 07:27:29 2018 us=559548 TUN/TAP device tun0 opened Fri Aug 24 07:27:29 2018 us=560899 TUN/TAP TX queue length set to 100 Fri Aug 24 07:27:29 2018 us=560931 do_ifconfig, tt->did_ifconfig_ipv6_setup=0 Fri Aug 24 07:27:29 2018 us=560949 /sbin/ip link set dev tun0 up mtu 1500 Fri Aug 24 07:27:29 2018 us=568979 /sbin/ip addr add dev tun0 10.8.0.2/24 broadcast 10.8.0.255 Fri Aug 24 07:27:29 2018 us=570458 /sbin/ip route add 192.168.122.29/32 dev ens3 Fri Aug 24 07:27:29 2018 us=575691 /sbin/ip route add 0.0.0.0/1 via 10.8.0.1 Fri Aug 24 07:27:29 2018 us=576933 /sbin/ip route add 128.0.0.0/1 via 10.8.0.1 Fri Aug 24 07:27:29 2018 us=579914 Initialization Sequence Completed